QID 730355
Date Published: 2022-02-28
QID 730355: VMware vRealize Operations Multiple Vulnerabilities (VMSA-2021-0018)
VMware vRealize Operations delivers self-driving IT operations management for private, hybrid, and multi-cloud environments in a unified, AI-powered platform.
Affected Versions(s):
VMware vRealize Operations Manager v8.4.0 before build number 18456799
VMware vRealize Operations Manager v8.3.0 before build number 18439216
VMware vRealize Operations Manager v8.2.0 before build number 18439241
VMware vRealize Operations Manager v8.1.x before build number 18442226
VMware vRealize Operations Manager v8.0.x before build number 18442174
VMware vRealize Operations Manager v7.5.0 before build number 18528915
QID Detection Logic
This QID sends the GET request to ui/login.action and checks for vulnerable version.
An unauthenticated malicious actor with network access to the vRealize Operations Manager API can read sensitive data and add new nodes to existing vROps cluster.
- VMSA-2021-0018 -
www.vmware.com/security/advisories/VMSA-2021-0018.html
CVEs related to QID 730355
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| VMSA-2021-0018 |
|